Dots are here: OpenAI's agent that Pro does not bring to Spain

Dots are here: OpenAI's agent that Pro does not bring to Spain
ContenidoContents

Today, 29 September, OpenAI introduced dots: always-on agents, with a name, with their own cloud computer, powered by GPT-6 Astra. The announcement sells them as someone who takes work off your plate and sometimes acts before you ask. The sheet that matters is the Help Center, updated today.

From Spain, Pro does not bring one.

Who gets one, and who pays

The rollout is gradual. It can take days to reach an account, and you have to be 18.

  • Pro, on web, mobile, and desktop: in ChatGPT’s markets except the European Economic Area, Switzerland, and the United Kingdom. Spain is inside that exclusion. A personal Pro plan, at $100, $200, or the new $500, does not open a dot from here.
  • Business Premium: in every region where ChatGPT already works. A Premium seat is $100 a month on annual billing, or $125 month to month. A Standard seat, at $20 or $25, does not get one. A Business workspace needs at least two paid seats.
  • Enterprise, Edu, and Healthcare: a beta. An admin has to turn it on. It ships off.

The first dot is included. There is no add-on charge on day one. Talking to it does not count toward your ChatGPT allowance. If you ask it to start or manage tasks in Codex or ChatGPT Work, those tasks draw on the usual allowance.

For the next month, dots usage does not count toward the allowance of eligible Pro, Business, and Enterprise plans. After that, OpenAI says it will publish the terms for each plan. The announcement, alongside that, talks about an allowance for deeper work, with extended limits in that first month, and about adding dots later or raising their speed or monthly volume. The price of that extra is not published.

The same day they shipped Pro 500, at $500 a month: the highest included usage of the Pro plans, and Astra Ultrafast in Work and Codex. Buying credits on Pro $100 or Pro $200 does not unlock it. They also shipped GPT-6.1 Sol, at $2 per million input tokens, $0.10 for cached input, and $10 output, in Work, Codex, and the API. Not in chat. A dot does not run on that Sol. It runs on Astra, at $10 and $50.

What it is, without the video

Each dot has a cloud computer, a browser, and the apps you connect. OpenAI says the plugin ecosystem covers more than 4,000. You can open that computer and look at what it is doing. You can also give it permission to use yours. If you do not, yours stays separate.

You talk to it in ChatGPT, on desktop, web, and mobile, and by voice. Also in Slack and Teams. Texting over iMessage or RCS is a separate beta, for Pro users in the United States only, and it is not available in Business or Enterprise workspaces. Setup happens in the desktop app or in a desktop browser. Mobile comes after.

The launch page tells five jobs with a pet name: a developer who receives pull requests, a launch that rewrites itself, a scientist, a sales proposal, a content creator. Those are scenes. There is no benchmark, no count of finished tasks, and no cost per task. A month ago I wrote that the agent in a loop is paid for on every turn. Here the turn does not stop when you close the laptop. The price of that turn, after the grace month, is not on the sheet.

What it may do alone, and what it may not

When you are not there, the dot looks for ways to help. They call it proactive research. Those tasks read, with read-only tools, the sources you have already allowed. They cannot send messages, change content in an app, or control the browser or the computer. What they find is saved as private notes for that dot. Any next step goes through the normal rules.

Before it sends an email or changes a file, a separate system, Auto-review, checks the step against your instructions, your rules, and the safety rules. If it blocks the step, it tells the dot why. Your approval cannot override a mandatory safety rule. Those controls live outside the environment the dot can change.

Some steps stay with you: changing a password, and moving money between accounts. A purchase with a card already saved at the merchant needs your approval. Permanently deleting data, installing or running software from an unrecognized source, and granting new security-sensitive access need a confirmation every time.

For sharing, the rule depends on the data. A medical history requires a named recipient. An email address or a phone number, by default, requires a class of recipient (“any airline”), and only a Custom Rule opens it further. The dot can draft those rules, but changing them needs your approval, and they cannot remove a mandatory confirmation.

Passwords, on supported sign-ins, do not enter the model’s context: the model pauses, the form sends the secret to the browser, and the dot continues already signed in. A secret written in a document the dot can read is still visible. That is the same cut I wrote about when letting an AI use your passwords: permission to use, not to see. Disconnecting an app stops new sharing. What the dot has already learned stays in its context until you reset it.

On personal plans, the “improve the model for everyone” switch decides whether the dot’s conversations and work are used for training. On Business, Enterprise, and Edu, that content is not used for training by default. OpenAI says it does not train directly on proactive-research threads or on the notes a dot leaves for itself. If one of those notes later enters a conversation that is eligible, that conversation may be used, depending on the setting.

If safety monitoring sees a problem, it can pause or stop the work. The text says it twice: a dot can be wrong, and consequential work has to be reviewed. Four days ago I wrote that a research agent published photos. That is not this product. It is the reason to read the safeguards page before the carousel.

Specialist dots are a different thing, and they are not a switch you flip yourself yet. Their own identity, their own credentials, and a pilot with OpenAI’s engineers for a bounded job inside a company: procurement, invoices, email marketing, support, contracts. The Microsoft Agent 365 integration is announced as work in progress.

Next to Grok Bot

OpenAI did not invent the computer of one’s own this afternoon. Grok Bot shipped on 11 August: several agents, always on, with a cloud computer, and the work continues with the laptop closed. I compare against the docs as of 21 September and the teams page of the 28th. There is no shared benchmark. What fits on the same row is the sheet.

Dot Grok Bot
Computer One per dot. Yours only if you connect it One per user. All of your bots share it
Several at once The first is included. The next ones come later, with no price Several already, in parallel. Each has its own screen. One bot, one computer-use task at a time
Where you talk ChatGPT, voice, Slack, and Teams Its app: macOS, Windows, Linux, iPhone, and Android. Voice too
Model GPT-6 Astra. No other Cursor chooses. Settings have no picker
Who gets in Pro outside the EEA, Switzerland, and the UK. Business Premium, in every ChatGPT region Any paid Cursor plan, Teams, or a linked SuperGrok, Plus, or Heavy. The sheet does not carve out the EEA
Allowance One month that does not count. After that, no published price Weekly, included in the plan. Extra usage is billed per token. With both Cursor and SuperGrok, it uses whichever has more allowance
Your machine A separate permission Separate. It asks every time by default. It can be set to never
Approval Auto-review. Passwords and moving money stay with you Auto Review: allow, ask, or deny. Passwords, two-factor, and CAPTCHAs hand the screen to you

The cut I care about is the computer. A dot has its own. On Grok Bot, files, cookies, and terminal credentials belong to the account, not to the bot. The docs say it plainly: do not use separate bots as a security boundary. If one signs in to the classroom, the others see that session. On dots, disconnecting an app stops new sharing, but what that dot has already learned stays in its context until you reset it. Two different filters.

Grok Bot can also watch you do a workflow once and save it as a routine. A dot looks for work on its own, read-only, and any step that changes something goes back through Auto-review. Both are called proactive. They are not the same thing.

From here, the one I can open is Grok Bot. It comes with the SuperGrok I already use, or with a paid Cursor plan. The allowance is weekly and, once it runs out, the extra is per token: that sheet has no grace month. At a company, an admin turns it on from the Cursor dashboard. Forcing Auto-review, the network, and team secrets are Enterprise controls. The company dot is still a beta and ships off.

What it means

For someone who writes code, a dot is not a new model. It is Astra, the one from 3 September, put inside a computer that keeps going when you stop, with a month in which that use does not count and with Codex and Work still counting as if you had launched them yourself. This afternoon’s cheap Sol is not inside it.

For someone in Spain on a personal Pro plan, “included at no extra cost” does not apply. The path OpenAI’s sheet leaves open is a Business Premium seat, in a workspace of at least two, at $100 or $125 a month, or waiting until Pro crosses the EEA. The agent with a computer that I can open from Madrid is Grok Bot. And if I open it, the computer does not belong to each agent. It belongs to the account.


Sources: Introducing dots, safety and privacy, getting started, ChatGPT release notes for 29 September, GPT-6.1 Sol, Grok Bot, the shared computer.

CompartirShare